From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4ht1Kp34s4z2xVj for ; Sun, 27 Sep 2026 10:45:02 +0000 (UTC) Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4ht1Kl0M6Nz2xJ1 for ; Sun, 27 Sep 2026 10:44:59 +0000 (UTC) Received: from [127.0.0.1] (localhost [127.0.0.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mail01.ipfire.org (Postfix) with ESMTPSA id 4ht1Kj5DDYzLs for ; Sun, 27 Sep 2026 10:44:57 +0000 (UTC) DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003ed25519; t=1790505897; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=2KU8mUsq9ajCGko6jmb0HhQJDXZLTgfjmEHe3RT3UFI=; b=RcXST/QVFesOUATyGs0jKlUM4846rchr+5CIvkJnJvTGHAumIrYTP/0hcAoCJ9wYIpTqyn dr7LEGbF0q/QhwDA== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ipfire.org; s=202003rsa; t=1790505897; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=2KU8mUsq9ajCGko6jmb0HhQJDXZLTgfjmEHe3RT3UFI=; b=IGUVt5bgRuOEDDAAyCRdHLgdpAOMbt4eaRe5Ygopjc22UN/WzVYy6R1605I3eTu2GTO80u 5Ppbu/UavKzexsqM6/+3onTl8/z5VQSsd341Yh6nAWZjf/+2DspA5ZH679o8tWPYbQFsDn HizOUTKJlX9D8s9B5fpeSgftnqmsQuYfIIhdM2YFqp3wVuhViY8NcEnkOufVsOQFwB13kV XybvlPslIBUboXMxX5AwUFVxauoVIxWGYjQlRrz/6fKYHLaT8CRB0HVeuZ2eY8zvgqhToS JjWYV6BYEL3AM+k6jMfDoEB17sJC4QRaL1VVY9V/+SaxvoQIrlp27ycs+u/ufw== Message-ID: Date: Sun, 27 Sep 2026 12:44:53 +0200 Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 Subject: Re: [PATCH] urlfilter: Remove bundled Toulouse blacklist To: development@lists.ipfire.org References: <20260827091639.4064898-1-p27m@orange.fr> <217EBED3-D400-4695-A345-816C7DD47207@ipfire.org> <6C039B7E-2BAF-45B7-9C87-A7D008EF3443@ipfire.org> Content-Language: en-GB From: Adolf Belka In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit Hi All, I am following up on this as it has not had any follow-up for a while.. If there is a concern on the potential impact of not having any bundled Toulouse blocklist in the URL Filter, an alternative would be to have a newer version of the Toulouse Blocklist that includes the symlinks approach that Toulouse started using earlier this year. Would that be a viable approach? That would then keep the current default status of having a blocklist defined but using one that has the symlinks and therefore does not end up with the problem of trying to create a symlink with the same name as an existing file. Regards, Adolf. On 07/09/2026 18:51, p27m wrote: > Hello Michael, > > Yes, I Build it and install master ISO (CU204) on my test virtual machine. > > SquidGuard starts without errors when the blacklist directory is empty (the patch preserves the custom list). > Naturally, no category-based filtering takes place until a blacklist has been downloaded. > > I also ran a test using only a custom blacklist. > In this case, SquidGuard starts normally, and the custom domain is correctly blocked. > > This point was documented in comment #13 of bug 13969: > https://bugzilla.ipfire.org/show_bug.cgi?id=13969#c13 > > Thus, removing the default blacklist does not prevent URLFilter/SquidGuard from starting or functioning. > The user can simply download or restore a blacklist later, or use only the custom blacklist. > > Best regards, > > Philippe > > Le 07/09/2026 à 17:22, Michael Tremer a écrit : >> Hello Phil, >> >> Yes, this makes sense so far. But what actually happens when squidGuard is being started with nothing? I remember that this list has been treated as a dummy. Did you test this case too? >> >> -Michael >> >>> On 29 Aug 2026, at 16:56, p27m wrote: >>> >>> Hi Michael, >>> >>> Thank you for your reply. >>> >>> The problem described in the bug report is actually quite simple. >>> >>> Currently, the blacklist included in the IPFire repository and installed with IPFire dates from June 15, 2005, so it is now obsolete. >>> Since March 2026, the University of Toulouse has changed some directories in its blacklist into symbolic links. >>> Therefore, when restoring a backup containing a blacklist downloaded after this change, `tar` can fail because symbolic links cannot replace existing directories. As a result, the backup restoration fails. >>> >>> @adolf previously added a fix to `backup.pl` which removes the existing contents of `/var/ipfire/urlfilter/blacklists/` before extracting the backup. >>> >>> However, I recently discovered that the problem could still occur when restoring a backup from a backup ISO. >>> >>> For this reason, I thought that the simplest solution, and the best way to avoid similar problems in the future, would be to remove the obsolete blacklist archive from the installation. >>> >>> This patch does not prevent URLFilter from working without an installed blacklist. It also ensures that the old blacklist shipped with IPFire cannot interfere with restoring a newer blacklist from a backup. >>> >>> I have tested the patch with upgrades, fresh ISO installations, and restoration of backups containing both the Toulouse blacklist and the IPFire DBL blacklist. >>> >>> Best regards, >>> >>> Philippe >>> >>> Le 29/08/2026 à 17:31, Michael Tremer a écrit : >>>> Thank you very much for this patch. >>>> >>>> I could not quite figure out what you want to achieve with this change. Is this data being shipped causing some problems? The bug report did not give me the information I was looking for either. >>>> >>>> All the best, >>>> -Michael >> >